|
|||||||||||
|
Solaris finger bug
From: Jim Mellander <jmellander(at)lbl.gov>
Date: Fri Jul 27 2007 - 14:17:39 EDT
Recently, we monitored a cracker from Eastern Europe, who ran 'finger 9@host' against a Solaris 7 box, and got the following result: Login Name TTY Idle When Where daemon ??? < . . . . > bin ??? pts/1 This is on a Solaris 7 box with the latest recommended patch set. This is not the same bug as described here: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1503 Below are snippets of Sun's response: Sun> The issue you have seen regarding a single digit argument is different Sun> as this form of ambiguous username returns user information for accounts Sun> on the system which meet one of the following criteria: Sun> Sun> + an empty GECOS field Sun> + leading spaces in the GECOS field Sun> + trailing spaces in the GECOS field Sun> + a GECOS field with two adjacent spaces Sun> This latter issue has been addressed in Solaris 10 and later at this Sun> time under bugID 4432153. > Thanks for your response. Do you intend to provide patches for older At this time there aren't any plans to address 4432153 in Solaris 8 or 9. As you may know Solaris 7 is no longer supported. If a service call was raised with Sun then patches for Solaris 8 and 9 could be generated. > Under RFC 1288, it seems there should be a mechanism to disable such There isn't a way to disable such behaviour as far as we can tell despite the SHOULD in the RFC. We agree the the behaviour of 'finger 9@host' returning information about accounts with "unusual" whitespace in the GECOS field is non-intuitive and was also considered incorrect which is why 4432153 was filed. Hope this helps. Does anyone know of other platforms which exhibit this odd behavior? -- Jim Mellander Incident Response Manager Computer Protection Program Lawrence Berkeley National Laboratory (510) 486-7204 The reason you are having computer problems is: Lawn mower blade in your fan need sharpeningReceived on Fri Jul 27 14:54:41 2007 This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:10:18 EDT |
||||||||||
|
|||||||||||